CVE-2024-40852
Description
A logic flaw in Assistive Access on locked iOS/iPadOS devices lets an attacker view recent photos without authentication, fixed in iOS 18 and iPadOS 18.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A logic flaw in Assistive Access on locked iOS/iPadOS devices lets an attacker view recent photos without authentication, fixed in iOS 18 and iPadOS 18.
Vulnerability
This issue resides in the Assistive Access feature of iOS and iPadOS. When the device is locked, an attacker may be able to see recent photos without authentication. The vulnerability is present in versions prior to iOS 18 and iPadOS 18, which were released on September 16, 2024 [1]. The issue was addressed by restricting options offered on a locked device.
Exploitation
An attacker must have physical access to the locked device and be able to interact with the Assistive Access interface. No additional credentials or special privileges are required beyond the ability to reach the device screen. By navigating the locked Assistive Access mode, the attacker can bypass the intended lockscreen protections to view recent photos.
Impact
Successful exploitation results in unauthorized disclosure of recent photos stored on the device. This is a confidentiality breach that exposes visual information without the user's consent. The attacker gains no other privileges or control over the device.
Mitigation
Apple fixed this vulnerability in iOS 18 and iPadOS 18, released on September 16, 2024. Users should update their devices to the latest OS versions. There are no workarounds documented apart from applying the update; the affected versions are those prior to iOS 18/iPadOS 18 [1].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: <=17.x (fixed in 18)
- Range: <=17.x (fixed in 18)
- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.